Moat Finance ("Moat Finance," "we," "us," or "our") provides personal finance software through our website, iOS app, desktop app, browser extension, and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, store, share, and protect information when you use the Service.
By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
1. Scope
This policy applies to:
- The Moat Finance web application at app.moatfinance.ai
- The Moat Finance iOS app
- The Moat Finance desktop app (cloud sync and local-only modes)
- The Moat Finance browser extension
- Our MCP (Model Context Protocol) server and other agent integrations you connect
When you use local-only desktop mode, most of your financial data stays on your device and is not transmitted to our servers. Section 8 describes that mode separately.
2. Information we collect
Account and authentication information
When you create an account, we collect:
- Name and email address
- Profile picture (if you sign in with Google or Apple, or upload one)
- Password (stored as a one-way hash if you register with email and password)
- Session tokens and device information for active login sessions
- Two-factor authentication settings (if enabled)
Google Sign-In
When you sign in with Google, we receive your name, email address, and profile picture from Google. We use this information solely to create and authenticate your Moat Finance account, maintain your profile, and provide the Service to you.
We do not use Google user data for advertising. We do not sell Google user data. We do not allow humans to read your Google user data except:
- When you give us explicit permission (for example, when you contact support about your account)
- For security purposes (such as investigating abuse or unauthorized access)
- To comply with applicable law
- In aggregated or anonymized form for internal operations
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Apple Sign-In
When you sign in with Apple, we receive your name and email address (or Apple's private relay email, if you choose that option). We use this information solely to create and authenticate your Moat Finance account.
Financial account data
If you connect financial accounts, we collect data made available through our financial data partners, such as:
- Account names, types, and masked account numbers
- Account balances and transaction history
- Institution names
- Investment holdings and related metadata
Connections are read-only. We never collect or store your bank login credentials. Authentication with your financial institution is handled directly by our data partners (such as Plaid, MX, or Finicity).
Data you create or upload
We store information you enter or generate in the Service, including:
- Transaction categories, rules, tags, and notes
- Budgets, forecasts, goals, and financial scenarios
- Insurance policy details and uploaded policy documents
- Real estate and investment records you add manually
- CSV imports and column mappings
- Household and sharing settings
- Preferences and application settings
AI and agent features (MCP)
Moat Finance provides an MCP (Model Context Protocol) server so you can connect external AI agents (such as Claude, ChatGPT, or Cursor) to your financial data. We do not operate an in-app AI chat. Your conversations and prompts stay with the AI provider you choose.
When a connected agent calls an MCP tool on your behalf, we process:
- Structured tool requests (tool name and parameters such as date ranges or filters)
- Financial data from your Moat account needed to fulfill that request, limited to the scopes you authorized
- Audit metadata (which tool was called, which client, timing, and non-content input summaries for security logging)
- Content you explicitly submit through write tools (such as feedback messages or saved memories), if you use those features
We do not receive or store the chat messages or prompts you send to your external AI agent. Those are handled by your AI provider under their privacy policy.
Billing information
If you subscribe to a paid plan, our payment processor Stripe collects your email and payment method details. We receive subscription status, plan type, and billing history from Stripe. We do not receive or store your full payment card number.
Usage and technical data
We collect limited technical and usage information to operate and improve the Service:
- Pseudonymous user identifiers in product analytics (via PostHog)
- Feature usage events (counts, booleans, and feature names — not financial content)
- Application logs for error monitoring and security (via Axiom)
- Browser type, device type, and general usage patterns
We do not send email addresses, merchant names, transaction descriptions, account numbers, or other personally identifiable financial content to our analytics tools.
Communications
If you contact us or receive transactional emails (such as household invites or account notifications), we process your email address and the content of those communications. Transactional email is delivered through our email provider Resend.
Browser extension
If you use the Moat Finance browser extension to sync retail purchase data, the extension collects purchase information from supported retailer websites you visit, only when you initiate or authorize a sync. This data is sent to your Moat Finance account to supplement your financial profile.
3. How we use your information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Sync and display your financial accounts, transactions, and related data
- Run categorization rules, forecasts, and other features you configure
- Fulfill MCP tool requests from connected AI agents at your request
- Authenticate you and protect your account (including optional two-factor authentication)
- Process subscriptions and manage billing
- Send transactional communications
- Monitor performance, diagnose errors, and prevent abuse
- Comply with legal obligations
We do not use your personal information for third-party advertising. We do not sell your personal information.
4. How we share your information
We share information only as described below. We do not sell personal information.
Service providers
We use trusted third-party providers to operate the Service. They process data on our behalf and only as instructed by us:
| Provider | Purpose | Data shared |
|---|---|---|
| Plaid, MX, Finicity | Financial account linking and transaction sync | Consent tokens, account identifiers, and financial data under your authorization |
| Google / Apple | Sign-in authentication | OAuth tokens; profile information as described above |
| Stripe | Subscription billing | Email, subscription plan, payment method (handled by Stripe) |
| PostHog | Product analytics | Pseudonymous user ID, event names, and non-sensitive usage metadata |
| Axiom | Operational logging | Structured application logs (no raw financial content or PII by policy) |
| Resend | Transactional email | Email address and message content for emails we send you |
| Vercel | Application hosting | Request metadata and application infrastructure |
| Neon | Database hosting | All cloud-stored user data in our primary database |
Agent and MCP connections
If you connect an external AI agent to Moat Finance via MCP or similar integrations, we share only the financial context you authorize for that connection. You control which tools and data scopes are enabled.
Household sharing
If you invite another user to your household, shared financial data becomes visible to household members according to the permissions you configure.
Legal requirements
We may disclose information if required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business transfers
If Moat Finance is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
5. Data retention
- Active accounts: We retain your data for as long as your account is active and as needed to provide the Service.
- Deleted accounts: When you delete your account, we permanently delete your personal data promptly. Connected financial institution access tokens are revoked.
- Backups: Residual copies in encrypted system backups may persist for up to 90 days before being overwritten.
- Audit logs: Security and audit logs may be retained for up to one year.
- Analytics: Aggregated, non-identifiable analytics may be retained indefinitely.
6. Your choices and privacy rights
Depending on where you live, you may have the following rights:
- Access: View your data within the Service at any time.
- Correction: Edit your transactions, categories, profile, and other data directly in the app.
- Export: Download a copy of your data from Settings > Security > Export My Data (JSON or CSV).
- Deletion: Permanently delete your account and all associated data from Settings > Security > Delete Account.
- Disconnect accounts: Revoke financial institution connections at any time.
- Opt-out of sale: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
California residents may have additional rights under the CCPA/CPRA. Users in the European Economic Area and United Kingdom may have additional rights under GDPR/UK GDPR, including the right to restrict processing and the right to object. To exercise any rights not available directly in the app, contact us at support@moatfinance.ai.
7. Security
We implement technical and organizational measures designed to protect your information, including:
- Encryption in transit (TLS) for all network communication
- Encryption at rest for sensitive fields, including financial institution access tokens
- Password hashing using industry-standard algorithms
- Optional two-factor authentication
- Read-only financial connections — we cannot initiate transactions on your behalf
- Access controls and logging policies that prohibit sensitive data in application logs
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at support@moatfinance.ai.
8. Local and offline mode
Moat Finance offers a desktop app with a local-only mode that stores your financial data in a SQLite database on your computer. In this mode:
- Your financial data is not uploaded to Moat Finance cloud servers
- You control backups and exports locally
- Cloud features (sync across devices, web access, MCP over the cloud) are unavailable
Authentication and optional cloud features in the desktop app may still communicate with our servers. The local database itself remains on your device.
9. Children's privacy
The Service is intended only for adults aged 18 or older. Use of the Service is not permitted by anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, contact us at support@moatfinance.ai and we will delete it.
10. International data transfers
Moat Finance is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. We take steps designed to ensure appropriate safeguards for international transfers where required by law.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through an in-app notice before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
12. Contact us
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us at:
Moat Finance
Email: support@moatfinance.ai
Website: moatfinance.ai